Exam PCNSE All QuestionsBrowse all questions from this exam
Question 49

A client is concerned about resource exhaustion because of denial-of-service attacks against their DNS servers.

Which option will protect the individual servers?

    Correct Answer: D

    To protect individual DNS servers from denial-of-service (DoS) attacks and prevent resource exhaustion, applying a classified DoS Protection Profile is the most appropriate measure. This profile allows for the specialized protection of specific critical resources such as DNS servers, which are common attack targets. Other options like enabling packet buffer protection on the Zone Protection Profile or using DNS sinkholing are broader measures that do not target individual server protection as precisely as a classified DoS Protection Profile.

Discussion
Edu147Option: D

Correct is D They want to protect just one specific server, if you apply the zone protection you are protecting the entire zone

Chris71Mach1

The explanation we all need. Thanks!

RipuOption: D

Answer:D

Barry_Allen

:D smiling face

woody_Option: D

https://docs.paloaltonetworks.com/pan-os/9-1/pan-os-admin/zone-protection-and-dos-protection/zone-defense/dos-protection-profiles-and-policy-rules/classified-versus-aggregate-dos-protection#id56c14277-0ecd-4e32-b3d3-7b616176204a D.

Kane002Option: D

D. Single protection is for DoS.

zuby76Option: D

D is the right answer Packet Buffer protection is indeed the way to protect against resource exhaustion, but it is not configured under DoS protection profile. It is directly enabled under Zones.

[Removed]Option: D

Correct is D DOS protection if for resources behind the firewall. Zone Protection is for the firewall.

lgkhanOption: D

D is correct.

bing2021Option: D

for one specific server

MarshpillowzOption: D

D is correct

PochexOption: D

Answer D is the correct one. Classified profiles protect individual critical resources, especially servers that users access from the internet, and are often attack targets, such as web servers, database servers, and DNS servers. Please refer to https://docs.paloaltonetworks.com/pan-os/10-1/pan-os-admin/zone-protection-and-dos-protection/zone-defense/dos-protection-profiles-and-policy-rules/classified-versus-aggregate-dos-protection

yazid0016Option: D

Correct answer : D

yazid0016Option: D

Correct answer is D

UFanatOption: D

D. Apply a classified DoS Protection Profile.

chris_fgtOption: D

D is the correct answer

ZabolOption: D

Definitely D is correct

YasserSaiedOption: D

D -- it couldn't be else

yogininangpalOption: D

D is the correct answer, for specific servers not the entire zone so correct answer is not A